Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
joushou
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
61.
▲
by
joushou
11y ago
+1, although a bit more information would be nice ("Use key for session XYZ"). I'm curious, how did you get that set up?
62.
▲
by
joushou
11y ago
ssh-agent, as a protocol-concept is not as broken as it sounds. It's just that the implemented interface (socket) is bad when combined with no user acknowledgment of sign requests. I think the worst part is that the agent doesn't
63.
▲
by
joushou
11y ago
Interactive selection for agent-forwarding only works for regular SSH, not sftp, due to having no way to enter input. If I get around to it, one could wrap sftp completely, so that the available servers simply show up as root-level director
64.
▲
by
joushou
11y ago
Exactly. And yes, Kerberos got it somewhat right, but as someone who have used configured and used it, it is quite the exercise to set up. It took ages to get working, and even then, it was slightly cumbersome to use.
65.
▲
by
joushou
11y ago
SFTP/SCP works if you use the ProxyCommand, or agent forwarding. Clients such as WinSCP support agent forwarding, at least. Not sure about FileZilla. I'm not a Windows user, so can't say. :/
66.
▲
by
joushou
11y ago
Not at the current time. Will implement, just haven't had the time. I mainly code on this during my daily commute between Denmark and Sweden. :)
67.
▲
by
joushou
11y ago
That's true. Some people complained that this isn't documented enough, so there is a wiki page for sshmuxd explaining what it does. Agent forwarding with sshmux should be safer than the general case, though, as the agent is handle
68.
▲
by
joushou
11y ago
sshmux gives fine-grained user controls. In the normal jumphost example, you can use ssh -W to connect to arbitrary ports and hosts on the network, poking around where you weren't intended (ssh -W is just netcat where the ssh server in
69.
▲
by
joushou
11y ago
Agent forwarding can be dangerous, yes, in the sense that you are giving the remote host you are connecting to (or jumphost in this case) permission to sign things with your private key. In the normal case, this is done through a socket, wh
70.
▲
by
joushou
11y ago
I'm the author of the project. The project is meant to ensure that you can allow multiple users access through a jump-host style mechanism, while not permitting any other "abuse" of the jump host. You can lock down SSH a lot,
71.
▲
by
joushou
11y ago
I understand, I just don't see where it is an improvement. My rant is mainly triggered by dynamic linking being the standard without many people questioning the usability. It rarely it works as intended, especially with versioned symbo
72.
▲
by
joushou
11y ago
A bit of dynamic linking reading: http://harmful.cat-v.org/software/dynamic-linking/ http://harmful.cat-v.org/software/dynamic-linking/versioned-... Dynamic linking is not synonymous w
73.
▲
by
joushou
11y ago
The original authors of dynamic linking concluded that the cost was way higher than the benefits, both in memory usage and general performance, but the client demanded it. Dynamic linking is the number one binary compatibility issue on Linu
74.
▲
by
joushou
11y ago
SSH with SOCKS5 tunnelling enabled does exactly this. The trick is that VPN's aren't allowed very often, so that's where the TLS tunnel trick steps in. You can use a VPN over TLS with serve2d if you want. I just find ssh -D50
75.
▲
by
joushou
11y ago
Yup, that's also why I added the ability to tunnel anything over a transport (the only implemented one being TLS). You can get the SSH client to connect over this either by using an openssl s_client trick, or by just using my little tu
76.
▲
by
joushou
11y ago
MySQL seems to use a server initiated protocol (which I always find to be a terrible idea, as it means that an evil client has to do very little to trigger a larger amount of traffic in return, potentially to a spoofed address). Postgres (w
77.
▲
by
joushou
11y ago
Uh, wow, the popularity just skyrocketed. It's 00:17 and I just came home from a concert, so bear with me maybe being a bit incoherent. First of all, I'd like to thank my wife, who helped motivate me, my parents, who you know, did
78.
▲
by
joushou
11y ago
Hopefully your "What's up with the name" section is better than mine!
79.
▲
by
joushou
11y ago
I guess the best way to find alternative solutions is to write one and have people tell you there's other like it! I genuinely didn't know there were so many doing equivalent things. I do think serve2d is considerably more flexibl
80.
▲
by
joushou
11y ago
Actually, yes, packet inspecting firewalls do. Hence the SSH over TLS, to make things stealthy.
81.
▲
by
joushou
11y ago
How well do you hear 1Hz? A 44.1KHz doesn't have a lot of frequencies outside of the audible range, but that's not really that relevant, as that's only a minor trim compared to the crazy things lossy compression algorithms